BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//swoogo.com//NONSGML kigkonsult.se iCalcreator 2.41.90//
CALSCALE:GREGORIAN
UID:37613861-3930-4962-b132-306633363064
BEGIN:VEVENT
UID:dee7c378d9b7c0500ba1745d1ca99f5aa3f41a33@swoogo.com
DTSTAMP:20260812T233928Z
DESCRIPTION:Network security for broadcast IP infrastructures is of vital i
 mportance as more and more broadcasters venture into these new workflows. 
 This paper will describe current workflows using the AMWA BCP-003 security
  best practices.\n\nWhile the open specifications allow for easy adoption 
 by the broadcast industry\, they are fully documented and would easily all
 ow man-in-the-middle attacks to retrieve vital device information\, such a
 s IP addresses\, for accessing control ports. Usage of those control ports
  by unauthorized personnel could lead to disruptions in the production cha
 in\, or worse.\n\nBCP-003 can be used to encrypt all API traffic with TLS 
 to initially prevent man-in-the-middle attacks. As there are many cipher s
 uites to choose from\, this paper describes why the current list of suites
  was chosen to cover both best security and compatibility with legacy broa
 dcast equipment with small computing performance. After a theoretical intr
 oduction\, the paper explains how a broadcast facility can practically dep
 loy the needed Public Key Infrastructure and how devices that are installe
 d after initial deployment can be added.\n\nFurthermore\, we will focus on
  AMWA IS-10 as a means of specifying authorization mechanisms to secure ac
 cess to NMOS APIs such as IS-04\, -05\, or -08. We will also explain the c
 urrent concept of an authorization server and how it can issue tokens for 
 controllers and nodes. In this way\, we can secure NMOS nodes against unwa
 nted access for starting/stopping/configuring media endpoints. The choice 
 of API for finding the server and retrieving tokens is closely linked to o
 ther NMOS APIs in order to allow for fast adoption.\n\nWhile integrating t
 he Authorization server into an existing IT infrastructure using common Us
 er Databases such as Active Directory is outside of the scope of BCP-003\,
  it is a necessary way to reduce the overhead of maintenance. A proof of c
 oncept will be presented in support of this.\n\nKeywords\nSMPTE ST 2210\, 
 NMOS\, security\, encryption\, APIs\, BCP-003\, AMWA
DTSTART:20191023T160000Z
DTEND:20191023T163000Z
LAST-MODIFIED:20260812T233928Z
LOCATION:San Francisco Room
SEQUENCE:0
STATUS:CONFIRMED
SUMMARY:Security for Discovery and Connection Management of SMPTE ST 2110 M
 edia Devices
TRANSP:OPAQUE
X-ALT-DESC;FMTTYPE=text/html:Network security for broadcast IP infrastructu
 res is of vital importance as more and more broadcasters venture into thes
 e new workflows. This paper will describe current workflows using the AMWA
  BCP-003 security best practices.<br /><br />\nWhile the open specificatio
 ns allow for easy adoption by the broadcast industry\, they are fully docu
 mented and would easily allow man-in-the-middle attacks to retrieve vital 
 device information\, such as IP addresses\, for accessing control ports. U
 sage of those control ports by unauthorized personnel could lead to disrup
 tions in the production chain\, or worse.<br /><br />\nBCP-003 can be used
  to encrypt all API traffic with TLS to initially prevent man-in-the-middl
 e attacks. As there are many cipher suites to choose from\, this paper des
 cribes why the current list of suites was chosen to cover both best securi
 ty and compatibility with legacy broadcast equipment with small computing 
 performance. After a theoretical introduction\, the paper explains how a b
 roadcast facility can practically deploy the needed Public Key Infrastruct
 ure and how devices that are installed after initial deployment can be add
 ed.<br /><br />\nFurthermore\, we will focus on AMWA IS-10 as a means of s
 pecifying authorization mechanisms to secure access to NMOS APIs such as I
 S-04\, -05\, or -08. We will also explain the current concept of an author
 ization server and how it can issue tokens for controllers and nodes. In t
 his way\, we can secure NMOS nodes against unwanted access for starting/st
 opping/configuring media endpoints. The choice of API for finding the serv
 er and retrieving tokens is closely linked to other NMOS APIs in order to 
 allow for fast adoption.<br /><br />\nWhile integrating the Authorization 
 server into an existing IT infrastructure using common User Databases such
  as Active Directory is outside of the scope of BCP-003\, it is a necessar
 y way to reduce the overhead of maintenance. A proof of concept will be pr
 esented in support of this.<br /><br /><br />\nKeywords<br />\nSMPTE ST 22
 10\, NMOS\, security\, encryption\, APIs\, BCP-003\, AMWA
END:VEVENT
END:VCALENDAR
